Skip to main content
← All Articles

Tag

#Android Security

18 articles

Advertisement

Open-Source Android AI Agent Hijacking Leads to Host System RCE
HIGH
Vulnerabilities

Open-Source Android AI Agent Hijacking Leads to Host System RCE

Learn how invisible text exploits open-source Android AI agents to trigger malicious code execution on host PCs via indirect prompt injection.

Runtime Rebel Intel
4 min read · Jul 21, 2026
HIGH
Malware

RedHook Android Malware: Abusing Wireless ADB for Local Shell Access

RedHook Android malware leverages Wireless Debugging to obtain shell-level privileges. Learn how this threat bypasses traditional security controls.

Runtime Rebel Intel
4 min read · Jul 12, 2026
MEDIUM
Vulnerabilities

Google Gemini Hijack: Command Injection via Messaging Notifications

Researchers demonstrate how Google Gemini voice assistant can be hijacked via malicious messaging notifications to control smart homes and start video calls.

Runtime Rebel Intel
4 min read · Jun 4, 2026
Google Gemini Hijacked on Android via Poisoned Notifications
HIGH
Vulnerabilities

Google Gemini Hijacked on Android via Poisoned Notifications

Researchers demonstrate how WhatsApp and Slack notifications can trigger indirect prompt injection in Google Gemini, leading to memory poisoning.

Runtime Rebel Intel
4 min read · Jun 3, 2026
HIGH
Vulnerabilities

Android and Linux Kernel Exploitation: CVE-2024-36971 and CVE-2024-21626

CISA adds Android CVE-2024-36971 and Linux CVE-2024-21626 to its KEV catalog following reports of active exploitation by sophisticated threat actors.

Runtime Rebel Intel
4 min read · Jun 3, 2026
HIGH
Vulnerabilities

CISA KEV Update: Active Exploitation of CVE-2022-0492 and CVE-2025-48595

CISA adds Linux Kernel and Android Framework vulnerabilities to its Known Exploited Vulnerabilities catalog. Prioritize patching CVE-2022-0492 and CVE-2025-48595.

Runtime Rebel Intel
3 min read · Jun 2, 2026

Advertisement

CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day
HIGH
Vulnerabilities

CVE-2025-48595: Android June 2026 Update Patches Exploited Zero-Day

Google's June 2026 security update fixes 124 vulnerabilities, including CVE-2025-48595, a zero-day privilege escalation flaw under active exploitation.

Runtime Rebel Intel
4 min read · Jun 2, 2026
HIGH
Identity & Access

Misconfigured MSAL for Android Exposes Microsoft Account Tokens

A vulnerability in the Microsoft Authentication Library for Android allowed unauthorized apps to intercept OAuth tokens, impacting billions of users.

Runtime Rebel Intel
4 min read · Jun 2, 2026
Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users
INFO
Threat Intel

Android Intrusion Logging: Enhancing Spyware Forensics for High-Risk Users

Google introduces Intrusion Logging for Android to capture persistent forensic data, aiding the detection of sophisticated spyware and state-sponsored attacks.

Runtime Rebel Intel
4 min read · May 13, 2026
7.3M Downloads: Analyzing Fraudulent Android Call History Apps
HIGH
Threat Intel

7.3M Downloads: Analyzing Fraudulent Android Call History Apps

Researchers discover 28 fraudulent Android apps on the Google Play Store that trick millions of users into expensive, fraudulent subscriptions.

Runtime Rebel Intel
4 min read · May 8, 2026
Google Android Binary Transparency: Defending Against Supply Chain Attacks
INFO
Supply Chain

Google Android Binary Transparency: Defending Against Supply Chain Attacks

Google expands Binary Transparency to Android apps, providing a public ledger to verify app integrity and mitigate risks of mobile supply chain attacks.

Runtime Rebel Intel
4 min read · May 6, 2026
INFO
Vulnerabilities

Google Android VRP 2024 Updates: $1.5M for Pixel Kernel Exploits

Google overhauls its Vulnerability Rewards Programs, increasing payouts for complex Android exploits while devaluing bugs easily identified by AI tools.

Runtime Rebel Intel
3 min read · May 5, 2026
INFO
Vulnerabilities

Google Adjusts Bug Bounties: $1.5M Android Reward and AI Shift

Google updates its Vulnerability Reward Program, increasing Android zero-click payouts to $1.5 million while adjusting Chrome rewards amid an AI security surge.

Runtime Rebel Intel
4 min read · May 1, 2026
EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass
HIGH
Vulnerabilities

EngageLab SDK Vulnerability: Protecting Crypto Wallets from Sandbox Bypass

A flaw in EngageLab SDK exposed 50 million Android users to data theft. Learn how attackers bypass the Android sandbox to access private cryptocurrency keys.

Runtime Rebel Intel
4 min read · Apr 10, 2026
HIGH
Vulnerabilities

Exposed Google API Keys in Android Apps Grant Gemini Access

Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.

Runtime Rebel Intel
5 min read · Apr 9, 2026
ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, & Cloud Evasion
HIGH
Threat Intel

ThreatsDay Bulletin: Pre-Auth Chains, Android Rootkits, & Cloud Evasion

Analysis of the latest ThreatsDay Bulletin covering critical pre-authentication exploit chains, stealthy Android rootkits, and advanced CloudTrail evasion techniques.

Runtime Rebel Intel
5 min read · Apr 2, 2026
MEDIUM
Threat Intel

Android Security Safeguards and UK Cyber Reporting Mandates

Analysis of new Android live threat detection features, the Operation Alice takedown, and updated UK cybersecurity reporting regulations for 2024.

Runtime Rebel Intel
3 min read · Mar 20, 2026
INFO
Vulnerabilities

Google VRP 2025: $17.1 Million Paid for Security Vulnerabilities

Google's Vulnerability Reward Program paid a record $17.1 million in 2025, highlighting critical security research trends in Android, Chrome, and AI systems.

Runtime Rebel Intel
3 min read · Mar 12, 2026